Simple Rules ordering has often been described as a confused mess dreamt up by incompetent developers. Nothing could be further from reality.
How Rules Order
Simple Rules are automatically ordered based on:
Source
- Devices [<n]
- Networks [<n]
- All Devices/All Networks
Note: All Devices is implemented in the firewall as “All Local Networks”.
Destination
- Apps [DPI]
- App Groups [DPI]
- IP Address [IP]
- Domain Name [IP]
- Region [GeoIP]
- Internet [WAN, VPN]
- Local Network [LAN]
Notes:
Internet is defined as anything that is not a Local Network. VPN networks are not considered Local Networks.
When using subnets in IP Address, use the network and broadcast address for the subnet start and end address. eg 192.168.1.0-192.168.1.255
Action
- Speed Limit [Allow]
- Allow
- Block